« A new attack: iPhone blogslurping | Main | Who Should be Liable? »

A Public Thank You to Private Reporters

I never really read Microsoft's vulnerability notices that closely, but for some reason when I scanned the news yesterday, the number of "privately reported" vulnerabilities seemed to jump out at me. I believe many of these folks are the unsung heroes in bugfinding - while I may not necessarily agree with what they are doing, I am sure they believe they are doing the right thing and it is clear that they have no ego motive in doing it.

Thank you, Private Reporters. While the vulnerability you found was better off unfound, at least you reported it in a way that minimized the risk to organizations and individuals around the world.

No, it won't be perfect - obviously, reverse engineering has reached a point where the details will likely be made public - but it does make exploits slightly less likely (unless they get packaged by others) and perhaps more importantly it (hopefully) delays the exploits in some manner.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345207f669e200e5505db60b8833

Listed below are links to weblogs that reference A Public Thank You to Private Reporters:

Comments

Pete, how goes? The names of the bug-finders sending in those "privately reported" issues are in the bulletins. It's always been that way.

_r

I think Pete is comparing people who report bugs privately to the vendor, versus those who post bugs publicly so everyone is aware of them at the same time.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment